Evidence used
- No CISA KEV confirmation is currently recorded.
BlackTreeCVE IntelligenceRed Hat Product Security · automation-controller-venv-tower-0:4.5.36-1.el8ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.4 for RHEL 8
Red Hat Product Security reports a critical vendor CVSS assessment and supplies remediation evidence. Validate product applicability and exposure while canonical CVE data is pending.
Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.
The vendor explicitly identifies these products or versions as containing the fix.
Red Hat Product Security reports a critical vendor CVSS assessment and supplies remediation evidence. Validate product applicability and exposure while canonical CVE data is pending.
Patch availableA flaw was found in Red Hat Ansible Automation Platform's automation- controller. When attaching an instance group to a schedule or a workflow job template node through the dedicated API relationship endpoint, the controller verifies only that the requesting user can read (view) the instance group, rather than that they hold use permission on it, unlike every other instance group assignment in the product. An authenticated user with read-only visibility of an instance group -- for example a system auditor -- can attach a use-restricted instance group, including the control plane group or another tenant's container group, to a schedule or workflow node they control. Their playbook then executes on the control plane node or within another tenant's execution environment, leading to privilege escalation and, in the control plane case, full compromise of the platform.
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. When attaching an instance group to a schedule or a workflow job template node through the dedicated API relationship endpoint, the controller verifies only that the requesting user can read (view) the instance group, rather than that they hold use permission on it, unlike every other instance group assignment in the product. An authenticated user with read-only visibility of an instance group -- for example a system auditor -- can attach a use-restricted instance group, including the control plane group or another tenant's container group, to a schedule or workflow node they control. Their playbook then executes on the control plane node or within another tenant's execution environment, leading to privilege escalation and, in the control plane case, full compromise of the platform.
The application performs an authorisation check, but it does not correctly enforce the required permission boundary.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may gain additional privileges.
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. When attaching an instance group to a schedule or a workflow job template node through the dedicated API relationship endpoint, the controller verifies only that the requesting user can read (view) the instance group, rather than that they hold use permission on it, unlike every other instance group assignment in the product. An authenticated user with read-only visibility of an instance group -- for example a system auditor -- can attach a use-restricted instance group, including the control plane group or another tenant's container group, to a schedule or workflow node they control. Their playbook then executes on the control plane node or within another tenant's execution environment, leading to privilege escalation and, in the control plane case, full compromise of the platform.
The application performs an authorisation check, but it does not correctly enforce the required permission boundary.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may gain additional privileges.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-863: Incorrect Authorization. The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Linked articles are downloaded and versioned as source evidence. A CVE mention or approved update relationship does not, by itself, verify a fix for every product branch.
Published 23 Sept 2026 · Last source change 24 Sept 2026, 05:58 UTC · CWE-863 · Incorrect Authorization
Missing structured fields: official CVE record, canonical affected-version range. Missing data is not evidence of low risk; review the primary advisory.